HRMungez
Features The app How it works FAQ العربية Start free
Mungez HR

Privacy Policy

How we collect, use and protect your data in Mungez HR

Effective date: 1 August 2026 Last updated: 1 August 2026

On this page

1) Who we are 2) Our role: controller or processor? 3) Data we collect 4) Why we use this data 5) Legal basis for processing 6) App permissions and why we ask for them 7) Sharing data with third parties 8) International data transfers 9) How we protect your data 10) Data retention 11) Account and data deletion 12) Your rights 13) Children's privacy 14) Third-party links 15) Changes to this policy Contact us
This policy explains what data we collect when you use Mungez HR, why we collect each type, who we share it with, and how you stay in control of it. It applies to our website, the web dashboard, the mobile app (Android and iOS), and our WhatsApp bot.

1) Who we are

Mungez HR is a product owned and operated by Mungez ("we", "us", "our"). Mungez HR is a human-resources SaaS platform used by companies to manage their workforce: attendance, leaves and permissions, salary advances, and payroll.

You can reach us about any privacy matter at privacy@getmungez.com.

2) Our role: controller or processor?

There are two distinct situations, and your rights differ between them:

  • Employee data: when a company subscribes to Mungez HR and enters its employees' data, the employer is the Data Controller and we act as a Data Processor on its behalf and under its instructions. If you are an employee and want your data corrected or deleted, please address your request to your company's HR department first — we can help route it.
  • Customer account data and website visitors: when you request a free trial, contact us, or browse our site, we act as the Data Controller directly.

3) Data we collect

We collect only what is needed to run the service. The categories are:

  • Account and identity data: name, mobile number, email address, profile photo (optional), password (stored hashed — we cannot read it), role and permissions, and preferred interface language.
  • Employment and HR data: job title, department, work location, employment type, hire and termination dates, contract details, leave balances and requests, permissions, salary-advance requests and instalments, and performance reviews.
  • Financial and payroll data: base salary, allowances and deductions, taxes and social insurance, payslips, and the bank account or wallet used for salary disbursement. This is sensitive data and is handled with our highest level of protection.
  • Attendance and location data: check-in and check-out timestamps, plus precise location (latitude/longitude) at the moment of check-in or check-out only, to verify that you are inside an approved work location. We do not track your location in the background and do not record your movements outside that moment.
  • Device identifiers and device binding: to prevent buddy-punching we bind an employee account to a single device. We store a hash of a random secret identifier, plus the browser/OS string (User-Agent) and the IP address of the last binding. We do not collect IMEI or device serial numbers.
  • Biometric data (when enabled): if fingerprint or face unlock is enabled, verification happens entirely on your device through the operating system. We only receive the pass/fail result. We never see, store, or transmit any biometric template to our servers.
  • Documents and files: documents you or your company upload (contracts, qualifications, national ID, certificates) and attachments added to requests.
  • Notifications: push notification tokens for your device, used to deliver request, approval, and payroll alerts.
  • Messaging data: when using our WhatsApp bot: your platform user ID, phone number, and the content of messages exchanged with the assistant in order to fulfil your request.
  • Usage and technical logs: in-app activity log (who changed what and when), error logs, IP address, and access timestamps — for security and troubleshooting.
  • Cookies: we use strictly necessary cookies only — session handling, keeping you signed in, remembering your language, and CSRF form protection. We do not use advertising or tracking cookies.

4) Why we use this data

  • Creating accounts, operating the service, and delivering its core features.
  • Validating check-in and check-out inside the geographic area approved by the employer.
  • Computing salaries, earnings, deductions and taxes, and issuing payslips.
  • Running approval chains for leaves, permissions and salary advances, and notifying approvers.
  • Sending operational notifications (request approved, payroll released, upcoming public holiday).
  • Protecting accounts and preventing fraud and abuse (including device binding).
  • Providing technical support and answering your enquiries.
  • Improving the service and diagnosing faults (on aggregated or anonymised data wherever possible).
  • Complying with applicable legal, tax and regulatory obligations.

5) Legal basis for processing

  • Performance of a contract: processing necessary to deliver the service contracted with your company.
  • Legal obligation: retaining tax and wage records as required by applicable law.
  • Legitimate interest: information security, fraud prevention, and service improvement.
  • Consent: for optional permissions such as location, camera and notifications — which you can withdraw at any time from your device settings.

6) App permissions and why we ask for them

The mobile app requests the permissions below, and you will never be asked for one without an explanation. Declining a permission only disables the related feature, not the rest of the app:

  • Location (while in use only): to verify you are inside your work location when checking in or out. Location is never used in the background.
  • Camera: to take a profile photo or capture a document to attach to a request — only when you choose to.
  • Files and media: to upload documents and attachments and to download PDF payslips.
  • Notifications: to deliver request, approval and payroll alerts.
  • Fingerprint / face recognition: to lock the app locally on your device when you enable it.

7) Sharing data with third parties

We do not sell your personal data, we do not rent it, and we never use it for targeted advertising. Sharing is limited to the following:

  • Your employer: HR managers and authorised managers at your company can view your employment data as part of the employment relationship and according to their in-app permissions.
  • Hosting and infrastructure providers: to operate servers, databases and backups, under binding data-processing agreements.
  • Messaging provider: WhatsApp (Meta) — only if your company enables that channel, and only as far as necessary to deliver messages.
  • Push notification providers: services that deliver notifications to Android and iOS devices.
  • AI service providers: when you use the assistant, your request text is sent for processing and a reply is returned. This data is not used to train models, and only the minimum necessary context is sent.
  • Government and judicial authorities: where there is an enforceable legal obligation or court order.
  • Merger or acquisition: data may transfer to the successor entity, with this policy continuing to apply, and we will notify you in advance.

8) International data transfers

Some services or backups may be hosted on servers outside the Arab Republic of Egypt. Where that happens, we apply appropriate contractual and technical safeguards so that your data receives protection no lower than that described in this policy.

9) How we protect your data

  • Full isolation per company: every company gets a physically separate database — no company's data ever mixes with another's.
  • Encryption in transit: all traffic is carried over HTTPS/TLS.
  • Hashed passwords: stored with one-way hashing and not recoverable — nobody on our side can read your password.
  • Hashed device identifiers: we store the fingerprint of the secret, never the secret itself.
  • Granular permissions: a role and permission system restricts each user to their own data.
  • Activity log: sensitive changes are recorded so unauthorised access can be traced.
  • Regular backups to reduce the risk of data loss.

That said, no method of electronic transmission or storage is 100% secure. In the event of a breach affecting your personal data, we will notify the responsible company and the competent authorities without undue delay and as required by law.

10) Data retention

  • We retain your company's data for as long as the subscription is active.
  • After the subscription ends or is cancelled, data remains available for export for 90 days, after which it is permanently deleted or anonymised.
  • We may retain wage records and financial documents for longer where tax or labour law requires it.
  • Error logs and technical logs are purged on a rolling basis within no more than 12 months.

11) Account and data deletion

You can request deletion of your account and its associated data at any time — from inside the app, or via our dedicated web deletion page without needing to install the app:

  • Deletion request page: https://hr.getmungez.com/account-deletion
  • Or email us at privacy@getmungez.com from the address or number registered on your account.

We action requests within 30 days at most. Note that if you are an employee of a subscribed company, we may need the employer's confirmation before deleting records tied to the employment relationship (such as wage records), because they are legally in the employer's custody — we will keep you informed either way.

12) Your rights

Under Egyptian Personal Data Protection Law No. 151 of 2020 and comparable legislation, you have the right to:

  • Know what data we hold about you, access it, and obtain a copy.
  • Correct inaccurate data or complete incomplete data.
  • Delete your data or restrict its processing, to the extent permitted by law.
  • Object to processing based on legitimate interest.
  • Withdraw your consent at any time, without affecting processing already carried out.
  • Port your data to another provider in a machine-readable format.
  • Lodge a complaint with the competent supervisory authority.

To exercise any of these rights, email us at privacy@getmungez.com. We respond within 30 days at most.

13) Children's privacy

Mungez HR is a workplace platform. It is not directed at children and is not available to anyone under 18 years old. We do not knowingly collect data from minors. If we learn that we have collected data from a child below the legal working age, we delete it immediately. If you are a parent or guardian and believe this has happened, contact us at privacy@getmungez.com.

14) Third-party links

The service may contain links to sites or apps we do not operate. We are not responsible for their privacy practices, and we recommend reviewing their policies before sharing any data with them.

15) Changes to this policy

We may update this policy from time to time. The last-updated date appears at the top of this page, and for any material change affecting your rights we will notify you by email or an in-app notice before it takes effect. Continuing to use the service after the change takes effect constitutes acceptance of it.

Contact us

For any question or request related to this page, reach us at:

Email
support@getmungez.com
Privacy email
privacy@getmungez.com
Website
https://hr.getmungez.com
Address
Arab Republic of Egypt
HRMungez

A complete Egyptian HR platform: attendance, leaves, payroll, and a mobile app — with a dedicated database per company.

Platform

Features The app How it works FAQ

Get started

Start free Admin sign-in support@getmungez.com

Legal

Privacy Policy Terms & Conditions Account & data deletion
© 2026 Mungez HR — HR Platform. All rights reserved.