Last updated: 1 July 2026
ZingKey respects your privacy and is committed to protecting the personal data entrusted to us.
This Privacy Policy explains how ZingKey collects, uses, discloses, stores and protects personal data when you:
- Visit https://zingkey.com or another website operated by ZingKey;
- Contact us, request a demonstration or submit an enquiry;
- Create or use a ZingKey account;
- Subscribe to product updates or marketing communications;
- Apply for a position with ZingKey;
- Attend a ZingKey event or webinar;
- Use ZingKey’s HR, payroll, workforce, talent, total-rewards, AI or related services; or
- Otherwise interact with ZingKey.
In this Privacy Policy, “ZingKey”, “we”, “us” and “our” refer to the ZingKey organisation responsible for the relevant website or service.
By accessing our website or providing personal data to us, you acknowledge that you have read this Privacy Policy.
1. Who We Are
ZingKey provides an AI-native software platform for Core HR, multi-country payroll, workforce management, talent management and total rewards.
Our website address is:
For privacy-related questions or requests, contact:
Data Protection Officer
ZingKey
Singapore
Email: support@zingkey.com
Please include “Privacy Request” in the subject line when contacting us about your personal data.
2. Our Role When Processing Personal Data
Our role depends on the context in which personal data is processed.
Website, Sales and Business Data
When ZingKey collects personal data directly through its website, marketing activities, sales process, recruitment activities or business operations, ZingKey generally determines why and how that data is processed.
In these circumstances, ZingKey acts as the organisation responsible for that personal data.
Customer and Employee Data
When an organisation uses the ZingKey platform to manage its employees, contractors, applicants, payroll or workforce, the customer organisation generally determines why the personal data is processed and how the platform is configured.
In these circumstances:
- The customer organisation is generally responsible for the personal data;
- ZingKey processes the personal data on the customer’s behalf and according to its documented instructions; and
- ZingKey may act as a data intermediary, processor or service provider, depending on the applicable law.
Employees, applicants, contractors and other individuals whose information has been entered into ZingKey by their organisation should normally direct privacy requests to that organisation first. ZingKey will assist its customers in responding to valid requests where required.
3. Personal Data We Collect
The personal data we collect depends on how you interact with ZingKey.
Information You Provide to Us
We may collect information that you provide directly, including:
- Your name;
- Business email address;
- Personal email address where appropriate;
- Telephone number;
- Company name;
- Job title and department;
- Country or business location;
- Company size and estimated employee count;
- Information submitted through contact, demo, subscription or support forms;
- Account login and authentication information;
- Communication preferences;
- Details contained in emails, support tickets or messages;
- Billing contact and transaction information;
- Information submitted for webinars, events or product trials;
- Résumés, employment history and other recruitment information; and
- Any other information you choose to provide.
Please avoid sending sensitive personal data through a general contact form unless it is necessary for your request.
Account and Platform Information
When you create or use a ZingKey account, we may collect:
- Account identifiers;
- Usernames;
- Authentication records;
- Organisation and workspace information;
- User roles and permissions;
- Login dates and times;
- Security and audit logs;
- Feature usage;
- Configuration settings;
- Support history; and
- Actions performed within the platform.
Passwords are stored using appropriate security controls and are not intended to be accessible in readable form.
Customer Data Processed Through ZingKey
Depending on the modules selected and how a customer configures the platform, Customer Data may include:
- Employee and contractor names;
- Contact information;
- Employment and engagement details;
- Job titles, departments and reporting relationships;
- Government-issued identifiers;
- Tax and statutory information;
- Payroll, compensation and bank-payment information;
- Leave, attendance, scheduling and timesheet records;
- Expense and reimbursement records;
- Performance, recruitment, learning and skills information;
- Benefits and total-rewards information;
- Documents, contracts, policies and forms;
- Emergency-contact and dependent information;
- Immigration, work-authorisation or residency information;
- Communications and workflow records; and
- Other information uploaded or generated by the customer.
ZingKey processes this information to provide the services selected and configured by the customer.
Customers are responsible for ensuring that they have an appropriate legal basis, authority or consent to upload and process personal data through the ZingKey platform.
Information Collected Automatically
When you visit our website or use our platform, we may automatically collect:
- Internet Protocol address;
- Browser type and version;
- Device type;
- Operating system;
- Language and time-zone settings;
- Referring website or source;
- Pages viewed;
- Links and buttons selected;
- Session duration;
- Login activity;
- Approximate location derived from an IP address;
- Error reports;
- Performance information;
- Cookie identifiers; and
- Security and fraud-prevention information.
We use this information to operate, secure, analyse and improve our website and services.
Information From Other Sources
We may receive information from:
- Your employer or organisation;
- Authorised administrators;
- Integration partners selected by a customer;
- Identity and authentication providers;
- Public business directories;
- Event and webinar partners;
- Professional networking platforms;
- Referral partners;
- Service providers; and
- Publicly available sources.
We may combine this information with information already held by ZingKey where permitted by law.
4. How We Use Personal Data
ZingKey may use personal data to:
- Operate and maintain our website;
- Provide, configure and support the ZingKey platform;
- Create and administer user accounts;
- Authenticate users and manage access permissions;
- Process payroll, workforce and HR workflows according to customer instructions;
- Respond to sales, demonstration and partnership enquiries;
- Provide technical support;
- Communicate about service updates, incidents and security matters;
- Process subscriptions, invoices and payments;
- Conduct customer onboarding and implementation;
- Provide product training;
- Improve product functionality, reliability and usability;
- Analyse website and product usage;
- Develop new services and features;
- Detect, investigate and prevent fraud, misuse and security threats;
- Maintain audit trails and business records;
- Enforce our contracts and acceptable-use requirements;
- Comply with legal, regulatory and statutory obligations;
- Manage recruitment and employment applications;
- Send marketing communications where permitted;
- Protect ZingKey, our customers, users and the public; and
- Establish, exercise or defend legal claims.
We will not use personal data for a materially different purpose without providing an appropriate notice or obtaining consent where required.
5. Legal Bases for Processing
Depending on your location and the circumstances, ZingKey may process personal data based on:
Contractual Necessity
Processing may be necessary to enter into or perform a contract, including providing an account, product trial, subscription, support service or customer implementation.
Legal Obligations
Processing may be necessary to comply with applicable laws, court orders, statutory requirements, accounting obligations or regulatory requests.
Legitimate Business Interests
We may process personal data where reasonably necessary for legitimate interests such as:
- Operating and improving our services;
- Securing our systems;
- Preventing fraud;
- Managing customer relationships;
- Responding to business enquiries;
- Maintaining appropriate records; and
- Developing relevant products and services.
Where required, we consider whether these interests are outweighed by an individual’s rights and interests.
Consent
We may rely on consent for certain activities, including optional cookies, marketing communications or other processing where consent is required.
You may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.
Customer Instructions
When ZingKey processes Customer Data on behalf of a customer, the customer is responsible for identifying the appropriate legal basis. ZingKey processes that data according to the customer’s documented instructions and the applicable agreement.
6. AI Features and Automated Processing
ZingKey may provide AI-assisted features such as:
- Policy and knowledge searches;
- Summaries;
- Draft communications;
- Workflow recommendations;
- Payroll or workforce exception detection;
- Document generation;
- HR reporting;
- Data explanations; and
- Customer-configured automated actions.
Customer Data may be processed by AI systems to generate responses, recommendations or actions requested by an authorised user.
ZingKey does not independently make hiring, termination, compensation, promotion or other employment decisions on behalf of customers. Customers remain responsible for:
- Configuring AI features;
- Reviewing generated outputs;
- Approving consequential actions;
- Ensuring appropriate human oversight; and
- Complying with applicable employment and data-protection laws.
AI-generated output may be incomplete or inaccurate and should be reviewed before it is relied upon.
Unless separately authorised or agreed in writing, ZingKey does not use Customer Data to train general-purpose AI models that are made available to other customers.
Where approved third-party AI or infrastructure providers are used, they are required to process information under contractual restrictions and only for the authorised purpose.
7. Cookies and Similar Technologies
ZingKey uses cookies and similar technologies to operate, secure and improve its website and services.
A cookie is a small file stored on your device when you visit a website.
We may use the following categories of cookies:
Strictly Necessary Cookies
These cookies are required for functions such as:
- User authentication;
- Account security;
- Session management;
- Load balancing;
- Fraud prevention; and
- Saving privacy preferences.
These cookies cannot always be disabled without affecting essential website or platform functionality.
Preference Cookies
These cookies remember information such as:
- Language;
- Region;
- Display settings;
- Login preferences; and
- Other user-selected settings.
Analytics Cookies
Analytics cookies help us understand:
- How visitors reach our website;
- Which pages are viewed;
- How long visitors remain on a page;
- Which features are used; and
- Whether errors or performance problems occur.
Where required by law, non-essential analytics cookies will only be activated after consent.
Marketing Cookies
Where used, marketing cookies may help us measure campaigns and present more relevant business communications.
We will request consent before using these cookies where required.
Managing Cookies
You can control cookies through:
- The cookie settings displayed on our website;
- Your browser settings;
- Device settings; or
- The controls provided by the relevant third-party service.
Blocking certain cookies may affect website or platform functionality.
8. Comments, Community Features and Public Submissions
Where comments, community features or public submissions are enabled, we may collect:
- The information entered into the submission form;
- Your IP address;
- Browser and device information; and
- Information used to detect spam, fraud or misuse.
Information submitted to a public area may be visible to other users or the public. You should not include confidential, sensitive or unnecessary personal data in public submissions.
If an avatar or profile-image service is enabled, a hashed version of your email address may be provided to that service to determine whether an associated profile image exists.
9. Uploaded Images and Files
If you upload images or other files, those files may contain metadata.
Images may contain embedded location information, including EXIF GPS data. Other users may be able to download a publicly accessible image and extract that information.
You should remove unnecessary location or device metadata before uploading media to a public area.
10. Embedded Content and Third-Party Websites
Our website may include embedded content such as:
- Videos;
- Maps;
- Social-media content;
- Images;
- Articles;
- Forms; or
- Other third-party services.
Embedded content may behave as though you visited the third-party website directly. The third party may collect information, set cookies or monitor your interaction with its content.
ZingKey does not control the privacy practices of external websites. You should review the privacy policy of each third party before providing personal data.
11. How We Disclose Personal Data
We may disclose personal data to the following categories of recipients.
Service Providers
We may use service providers for:
- Cloud hosting;
- Data storage;
- Security and monitoring;
- Email delivery;
- Customer support;
- Analytics;
- Customer relationship management;
- Authentication;
- Communications;
- Payment processing;
- Professional services;
- AI infrastructure; and
- Product development.
Service providers are permitted to process personal data only for authorised purposes and are required to apply appropriate confidentiality and security protections.
Customer Organisations
Where you use ZingKey through your employer or another organisation, authorised administrators and representatives of that organisation may access information associated with your account and employment relationship.
Integrations Selected by Customers
Customers may connect ZingKey with payroll providers, accounting systems, identity providers, collaboration tools, banks, government systems or other applications.
Information may be exchanged with these services according to the customer’s configuration and instructions.
Professional Advisers
We may disclose information to auditors, accountants, lawyers, insurers, consultants and other professional advisers where reasonably necessary.
Government and Regulatory Authorities
We may disclose information where required to:
- Comply with applicable law;
- Respond to a lawful request;
- Comply with a court order;
- Assist a regulatory or law-enforcement authority;
- Protect legal rights; or
- Prevent serious harm, fraud or security threats.
Corporate Transactions
If ZingKey is involved in a merger, acquisition, financing, restructuring, sale of assets or similar transaction, personal data may be disclosed to relevant advisers and transaction participants, subject to appropriate confidentiality protections.
ZingKey does not sell or rent personal data for monetary consideration.
12. International Data Transfers
ZingKey operates a multi-country platform and may process personal data in Singapore or other approved locations.
Personal data may be transferred to or accessed from a country different from the country in which it was collected when:
- A customer operates across multiple countries;
- An authorised user accesses the platform from another jurisdiction;
- A customer selects a particular hosting region;
- A service provider operates internationally; or
- A transfer is required to provide the requested service.
Where required, ZingKey uses appropriate safeguards designed to ensure that transferred personal data receives a standard of protection comparable to that required under applicable law.
These safeguards may include:
- Contractual data-protection obligations;
- Standard contractual clauses;
- Data-processing agreements;
- Transfer assessments;
- Access restrictions;
- Encryption;
- Regional hosting controls; and
- Other legally recognised transfer mechanisms.
Customers should review their ZingKey agreement and data-processing addendum for service-specific information about hosting locations and international transfers.
13. Data Retention
ZingKey retains personal data only for as long as reasonably necessary for the purpose for which it was collected and for legitimate legal or business requirements.
Retention periods may depend on:
- The type of information;
- The duration of the customer relationship;
- Customer instructions;
- Contractual requirements;
- Statutory payroll, tax or employment-record obligations;
- Security and fraud-prevention requirements;
- Dispute-resolution requirements;
- Applicable limitation periods; and
- Legal or regulatory obligations.
Website enquiries may be retained for the period necessary to respond, manage the business relationship and maintain appropriate records.
Account and transaction records may be retained for the duration of the account and for an appropriate period after termination.
Customer Data is retained according to the applicable customer agreement, configuration and deletion instructions.
When personal data is no longer required, we will take reasonable steps to:
- Delete it;
- Anonymise it;
- Remove the means by which it can be associated with an individual; or
- Securely isolate it until deletion is completed through normal backup cycles.
14. Data Security
ZingKey uses reasonable administrative, organisational and technical safeguards designed to protect personal data against:
- Unauthorised access;
- Unauthorised collection;
- Misuse;
- Disclosure;
- Copying;
- Modification;
- Accidental loss;
- Destruction; and
- Similar risks.
Depending on the service and risk, these safeguards may include:
- Encryption in transit and at rest;
- Identity and access controls;
- Role-based permissions;
- Multi-factor authentication;
- Audit logging;
- Secure software-development practices;
- System monitoring;
- Vulnerability management;
- Backup and recovery procedures;
- Employee confidentiality obligations;
- Security training;
- Supplier assessments; and
- Incident-response procedures.
No method of internet transmission or electronic storage is completely secure. ZingKey cannot guarantee absolute security, but we will continue to maintain safeguards appropriate to the nature of the information and the risks involved.
If a data breach occurs, we will assess and respond to it and provide required notifications in accordance with applicable law.
15. Your Privacy Rights
Your rights depend on where you live and the laws that apply.
Subject to applicable conditions and exceptions, you may have the right to:
- Request access to personal data held about you;
- Request information about how your personal data has been used or disclosed;
- Request correction of inaccurate or incomplete information;
- Request deletion or erasure;
- Request restriction of processing;
- Object to certain processing;
- Withdraw consent;
- Request a portable copy of certain information;
- Opt out of certain marketing communications;
- Ask questions about automated processing;
- Lodge a complaint with a relevant data-protection authority; and
- Exercise other rights provided under applicable law.
You will not be discriminated against for exercising a legally protected privacy right.
Requests Relating to Customer Data
If your data was provided to ZingKey by your employer, prospective employer or another customer organisation, please submit your request to that organisation.
ZingKey will provide reasonable assistance to the customer in responding to valid requests.
Requests Relating Directly to ZingKey
For personal data controlled directly by ZingKey, email:
Use the subject line:
Privacy Request
Please describe:
- Your relationship with ZingKey;
- The right you wish to exercise;
- The information concerned; and
- Any details that may help us locate the relevant records.
We may need to verify your identity before processing a request. We may also request proof that an authorised representative has permission to act on your behalf.
We will respond within the period required by applicable law.
Some requests may be limited or refused where permitted by law, including where information must be retained for security, contractual, administrative, legal or regulatory reasons.
16. Marketing Communications
ZingKey may send product announcements, event invitations, newsletters and other business communications where permitted by law.
You can unsubscribe by:
- Selecting the unsubscribe link in an email;
- Updating your communication settings; or
- Contacting support@zingkey.com.
Unsubscribing from marketing communications does not prevent us from sending important non-marketing messages such as:
- Account notifications;
- Security alerts;
- Service updates;
- Billing notices;
- Support responses; or
- Contractual communications.
17. Children’s Personal Data
The ZingKey website and platform are intended for organisations and authorised business users. They are not directed at children for independent consumer use.
Customers may use the platform to store dependent, beneficiary or family information where relevant to employment, benefits or payroll administration. In those circumstances, the customer is responsible for ensuring that the information is collected and processed lawfully.
If you believe that personal data relating to a child has been provided to ZingKey improperly, contact support@zingkey.com.
18. Third-Party Integrations
Customers may enable integrations with third-party products and services.
When an integration is enabled:
- Personal data may be transferred between ZingKey and the third party;
- The customer determines which integration is enabled;
- The customer is responsible for configuring the integration appropriately; and
- The third party’s own privacy policy and terms may apply.
ZingKey is not responsible for a third party’s independent use of personal data after that data has been transferred according to the customer’s instructions.
19. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- Changes to our services;
- New features;
- Changes to our data practices;
- Legal or regulatory developments; or
- Security and operational requirements.
The updated version will be published on this page with a revised “Last updated” date.
Where changes are material, we may provide additional notice through our website, platform or email.
20. Contact Us
For questions, concerns, complaints or requests relating to privacy or personal data, contact:
Data Protection Officer
ZingKey
Singapore
Email: support@zingkey.com
Website: https://zingkey.com
We will review privacy concerns and respond in accordance with applicable data-protection laws.