sally.

Effective May 10, 2026

Privacy Policy

This Privacy Policy describes how Advark Pte. Ltd. (β€œAdvark,” β€œwe”) collects, uses, and protects information when you use Sally (the β€œService”). Sally is an HR tool used by founders and operators in Southeast Asia to manage hiring, onboarding, and offboarding.

This is a placeholder policy for our early-access cohort. It will be replaced with a counsel-reviewed version before general availability.

1. Information we collect

Founder accounts. Name, email, profile picture, and Google account ID via Google OAuth.

Company data you submit. Legal entity details, payroll provider credentials, document templates, integration tokens (Slack, Telegram, Dropbox Sign, Google Workspace, payroll providers).

Employee data you submit. Names, contact details, national ID numbers (NRIC, FIN, MyKad, KTP, passport), bank accounts, date of birth, address, employment details, compensation, equity, tax residency.

Conversations. Messages sent to Sally via the web dashboard, Slack, Telegram, or WhatsApp, plus the actions she takes in response.

Service operations. Logs, IP addresses, timestamps, user-agent strings, and basic device metadata for security and debugging.

2. How we use information

  • To provide and operate the Service (drafting offers, syncing payroll, provisioning IT, generating tax documents).
  • To authenticate you and protect your workspace.
  • To send transactional emails (welcome sequences, candidate forms, approval notifications).
  • To improve and debug the Service using aggregated, de-identified usage data.
  • To comply with legal obligations.

3. AI processing

Sally uses third-party large language models (currently Anthropic Claude) to generate drafts and respond to chat. Customer Data is sent to the model provider only as required to fulfill the immediate request. We do not permit model providers to use your data to train their models.

Sensitive personal data (national IDs, bank account numbers, dates of birth) is encrypted at rest and is never included in prompts to model providers unless explicitly required for the task.

4. Storage and security

  • Customer Data is stored on managed PostgreSQL infrastructure (Supabase, hosted in the AWS Asia Pacific region).
  • Sensitive PII fields use envelope encryption with per-tenant data keys, rooted in cloud KMS.
  • Access to production systems requires SSO and is logged.
  • Files (signed contracts, payslips) are stored in encrypted object storage with signed URLs.

5. Sharing

We share Customer Data only with the integrations you explicitly connect (e.g., Google Workspace, Talenox, Slack, Dropbox Sign), and with sub-processors necessary to operate the Service:

  • Supabase β€” managed database, file storage, authentication.
  • Anthropic β€” large language model inference.
  • Vercel β€” application hosting.
  • Resend β€” transactional email delivery.
  • Inngest β€” workflow orchestration.

We do not sell personal data to third parties.

6. Your rights

Subject to applicable law (PDPA in Singapore and Malaysia, UU PDP in Indonesia, GDPR where it applies), you may request access to, correction of, or deletion of your personal data. Email privacy@sallythehrlady.com.

Employee data is controlled by your employer (the founder using Sally). Employees should direct data subject requests to their employer first; we will assist as a data processor.

7. Retention

We retain Customer Data for the life of your account plus 30 days, after which it is deleted from production systems. Backups are rotated within 90 days.

8. International transfers

Data may be processed outside your country of residence. We rely on the appropriate transfer mechanism for each jurisdiction (e.g., ASEAN Model Contractual Clauses, GDPR Standard Contractual Clauses).

9. Children

The Service is not intended for individuals under 16. We do not knowingly collect data from children.

10. Changes

Material changes to this policy will be announced via the dashboard or by email at least seven days before taking effect.

11. Contact

Questions? Email privacy@sallythehrlady.com or write to Advark Pte. Ltd., Singapore.